Re: [Freeipa-users] Sudo command not working

2015-08-13 Thread Dewangga Bachrul Alam
Hello! Should I reboot the machine after changing sudo.conf file? On 08/12/2015 09:26 PM, Jakub Hrozek wrote: On Wed, Aug 12, 2015 at 07:44:15PM +0700, Dewangga Bachrul Alam wrote: Hello! On 08/12/2015 07:36 PM, Jakub Hrozek wrote: On Wed, Aug 12, 2015 at 07:30:52PM +0700, Dewangga Bachrul

Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA

2015-08-13 Thread Youenn PIOLET
Hi Matt - CentOS : Did you copy ipasam.so and change your smb.conf accordingly? sambaSamAccount is not needed anymore that way. - Default IPA Way : won't work if your Windows is not part of a domain controller. DOMAIN\username may work for some users using Windows 7 - not 8 nor 10 (it did for me

Re: [Freeipa-users] Sudo command not working

2015-08-13 Thread Dewangga Bachrul Alam
Hello! On 08/13/2015 03:09 PM, Jakub Hrozek wrote: On Thu, Aug 13, 2015 at 03:01:40PM +0700, Dewangga Bachrul Alam wrote: Hello! Should I reboot the machine after changing sudo.conf file? No, it's read by sudo on every invocation. There is no sudo deamon or such. Yes, I found the

Re: [Freeipa-users] IDM/ipa slow login

2015-08-13 Thread seli irithyl
In the logs, there is lots of warnings concerning pki tomcat server : Aug 13 09:51:56 lead.bioinf.local systemd[1]: Started The Apache HTTP Server. Aug 13 09:51:56 lead.bioinf.local systemd[1]: Starting system-pki\x2dtomcatd.slice. Aug 13 09:51:56 lead.bioinf.local systemd[1]: Created slice

Re: [Freeipa-users] IDM/ipa slow login

2015-08-13 Thread Jakub Hrozek
On Thu, Aug 13, 2015 at 12:12:03PM +0200, seli irithyl wrote: In the logs, there is lots of warnings concerning pki tomcat server : Aug 13 09:51:56 lead.bioinf.local systemd[1]: Started The Apache HTTP Server. Aug 13 09:51:56 lead.bioinf.local systemd[1]: Starting

Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA

2015-08-13 Thread Matt .
Hi Youenn, OK thanks! this takes me a little but futher now and I see some good stuff in my logging. I'm testing on a Windows 10 Machine which is not member of an AD or so, so that might be my issue for now ? When testing on the samba box itself as my user I get: [myusername@smb-01 ~]$

Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA

2015-08-13 Thread Matt .
Hi, I might have found somthing which I already seen in the logs. I did a smbpasswd my username on the samba server, it connects to ldap very well. I give my new password and get the following: smbldap_search_ext: base = [dc=my,dc=domain], filter =

Re: [Freeipa-users] IDM/ipa slow login

2015-08-13 Thread seli irithyl
Here's the sssd_domain log part during an ssh (Thu Aug 13 15:22:31 2015) [sssd[be[bioinf.local]]] [be_get_account_info] (0x0200): Got request for [0x3][1][name=test] (Thu Aug 13 15:22:31 2015) [sssd[be[bioinf.local]]] [be_req_set_domain] (0x0400): Changing request domain from [bioinf.local] to

Re: [Freeipa-users] Kerberized NFS with Synology NAS

2015-08-13 Thread Roberto Cornacchia
After some more investigation, I feel the problem I described can be considered off topic, sorry about that. Initially I had the impression it could have been more freeIPA-related. It is sometimes difficult to tell whether the issue would show up regardless of using freeIPA or not. Should anyone

Re: [Freeipa-users] Kerberized NFS with Synology NAS

2015-08-13 Thread Alexander Bokovoy
On Thu, 13 Aug 2015, Roberto Cornacchia wrote: After some more investigation, I feel the problem I described can be considered off topic, sorry about that. Initially I had the impression it could have been more freeIPA-related. It is sometimes difficult to tell whether the issue would show up

[Freeipa-users] time restricted access

2015-08-13 Thread Marcelo Roccasalva
Hello, I've installed freeIPA 4.1.0 under CentOS 7 and I need to restric authentication to one or more time ranges but I failed to find such a configuration... TIA -- Marcelo ¿No será acaso que esta vida moderna está teniendo más de moderna que de vida? (Mafalda) -- Manage your subscription

Re: [Freeipa-users] time restricted access

2015-08-13 Thread David Kupka
On 13/08/15 17:01, Marcelo Roccasalva wrote: Hello, I've installed freeIPA 4.1.0 under CentOS 7 and I need to restric authentication to one or more time ranges but I failed to find such a configuration... TIA Hello, you're probably looking for Time-Based Account Policies. This is

[Freeipa-users] users- ssh keys self service

2015-08-13 Thread Janelle
Hi, So I still have been unable to find the problem with blank screens for users when they login to the gui and can not manage anything other than OTP. Out of the box, vanilla install of FreeOTP on RHEL 7.x and using IPA 4.1.4, a user logs in, you see ALL the fields for a split second,

Re: [Freeipa-users] users- ssh keys self service

2015-08-13 Thread Janelle
AHA!!! The problem is found, but the solution eludes me. Any user migrated in compat mode has the problem. NEW users do not. Thoughts? Ideas? troubleshooting? What do I need to make visible for users to edit their settings? ~J On 8/13/15 9:58 AM, Janelle wrote: Hi, So I still have been

Re: [Freeipa-users] IDM/ipa slow login

2015-08-13 Thread John Obaterspok
Hi Seli, In /etc/sssd/sssd.conf add below: selinux_provider=none to the domain section. Then restart sssd. -- john 2015-08-13 16:23 GMT+02:00 seli irithyl seli.irit...@gmail.com: Here's the sssd_domain log part during an ssh (Thu Aug 13 15:22:31 2015) [sssd[be[bioinf.local]]]

[Freeipa-users] reverse DNS lookup does not work

2015-08-13 Thread Nikola Kržalić
reverse DNS lookup stopped working after I broke some replication agreements (perhaps unrelated, but worth mentioning). Regular A records resolve fine. The records can be seen in LDAP (using ldapsearch with GSSAPI after kinit -t /etc/named.keytab): the zone: # 0.63.10.in-addr.arpa., dns,

[Freeipa-users] ipa directory inconsistencies

2015-08-13 Thread Nguyen, Alicia
Hi, I'm having an issue re-adding a client to freeipa (same hostname). When I removed the client from the domain I uninstalled freeipa on the client (using ipa-client-install --uninstall), removed the keytab, and ran ipa host-del FQDN on the the freeipa master. Everything has been rebooted. I

Re: [Freeipa-users] Kerberized NFS and home automount issues

2015-08-13 Thread Prasun Gera
Where are you trying to create the home directories ? Is your NFS server the same as the IPA server ? You can only create home directories on the NFS home server unless the nfs-client sees the export option no_root_squash. That is not recommended though. On Thu, Aug 13, 2015 at 9:49 AM, Youenn

Re: [Freeipa-users] Having problem with pwd_expiration

2015-08-13 Thread Rob Crittenden
Dewangga Bachrul Alam wrote: I've tried both of them (web ui CLI), still no luck. Screenshoot attached, the password expired not follow the global_policy. I've create another new user, it was same with user `subhan`. The password expired not follow global_policy.